Why Should I Care? โ€” 2026-08-31 | ๐Ÿ”ด 10 HIGH ยท ๐ŸŸก 8 MEDIUM ยท ๐Ÿ”ต 73 RADAR ยท โšช 54 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-08-31

91 vendor intel items scanned  |  ๐Ÿ”ด 10 HIGH  |  ๐ŸŸก 8 MEDIUM  |  ๐Ÿ”ต 73 RADAR  |  โšช 54 FILTERED

๐Ÿ”ด Critical โ€” action required:

  1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-21962) โ€” Yes, if you run Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in: improper access control allows unauthorized access, actively exploited in the wild.
  2. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-60004) โ€” Yes, if you run Gitea versions 1.15.0 - 1.15.5, 1.16.0 - 1.16.2: code injection vulnerability, actively exploited in the wild.
  3. CISA Adds Six Known Exploited Vulnerabilities to Catalog (CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, CVE-2026-8452) โ€” Yes, if you run any of the affected versions of Red Hat, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, or Citrix NetScaler: these vulnerabilities are actively exploited and pose significant risks.
  4. All-Line Equipment Company Fuel-Boss (CVE-2018-19518, CVE-2019-11043) โ€” Yes, if you run All-Line Equipment Company Fuel-Boss V1 Standard, Portal, Master/Slave, or Backflush Systems with PHP_7.1.5: unauthenticated RCE, potentially exploited.
  5. CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2023-49105, CVE-2026-53362, CVE-2026-66384) โ€” Yes, if you run any of the affected versions of ownCloud, Linux Kernel, or JFrog Artifactory: these vulnerabilities are actively exploited and pose significant risks.
  6. FURUNO FA-50 Class B AIS Transponder (CVE-2026-59769) โ€” Yes, if you run any version of FURUNO FA-50 Class B AIS Transponder: hard-coded credentials and missing authentication allow attackers to alter device settings.
  7. Ebyte NE2-D11 (CVE-2026-73125, CVE-2026-73809, CVE-2026-73839) โ€” Yes, if you run Ebyte NE2-D11 Firmware FW-9167-0-11: critical vulnerabilities allow unauthorized access, sensitive data disclosure, and device disruption.
  8. Applied Systems Engineering ASE2000 V2 Communications Test Set (CVE-2018-1285, CVE-2026-18717) โ€” Yes, if you run Applied Systems Engineering ASE2000 V2 versions 2.25-2.37: critical vulnerabilities allow arbitrary file access, network requests, and TLS interception.
  9. Ebyte NA111-M (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977) โ€” Yes, if you run Ebyte NA111-M Firmware 9013-2-17: multiple critical vulnerabilities allow unauthenticated access and full device compromise.
  10. Xiiaozet LK100W (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) โ€” Yes, if you run Xiiaozet LK100W <2.1.240: unauthenticated RCE, OS command injection, and authentication bypass.

Everything else can wait.

๐ŸŸก Medium โ€” review when time permits:

  1. Zoneminder โ€” Yes, if you run Zoneminder 1.37.48 or 1.38.3: authenticated users can execute arbitrary commands on your server, leading to full Remote Code Execution (RCE).
  2. Rently Smart Home โ€” Yes, if you run Rently Smart Home <=20.1.0: attackers can access sensitive information and override user permissions, including the Master Pin.
  3. Bendix EC80 Brake ECU โ€” Yes, if you run any of the affected Bendix EC80 Brake ECU versions: an attacker can disable critical vehicle functions like ABS and steering assist, potentially causing a crash.
  4. PayRange API โ€” Yes, if you run any version of PayRange API: unauthenticated access to sensitive information and potential device modification, actively exploitable.
  5. Siemens SIMATIC IoT2050 Advanced โ€” Yes, if you run SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) versions < 4.3.4.1: unauthenticated attackers can execute arbitrary code with maximum privileges.
  6. Mitsubishi Electric Multiple FA Products (Update D) โ€” Yes, if you run any of the affected Mitsubishi Electric CC-Link IE TSN modules <=09: remote attackers can cause a DoS, timeout, or communication delay.
  7. Mitsubishi Electric CNC Series (Update A) โ€” Yes, if you run any affected version of Mitsubishi Electric CNC Series (Update A): unpatched systems can be remotely crashed, causing a denial-of-service.
  8. Vulnerability in OpenSSL library โ€” Yes, if you run Fortinet products using affected OpenSSL versions: unpatched systems can be made unresponsive via crafted certificates, leading to a denial of service.

๐Ÿ”ต 15 items on the radar โ€” see below โ†“


Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now


CISA Adds One Known Exploited Vulnerability to Catalog

CISA Advisories [CISA KEV] | CVE-2026-21962

โ“ Why Should I Care?
Yes, if you run Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in: improper access control allows unauthorized access, actively exploited in the wild. Patch now.

๐ŸŽฏ Affected versions: Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in versions affected

๐ŸŽญ In plain English:
Your web server or proxy plug-in has a flaw that lets attackers sneak in without proper credentials. They can access sensitive data or control your server, causing serious disruptions. For example, an attacker could steal customer data or redirect traffic to malicious sites.

๐Ÿ”ง Prerequisites:

  • The server or plug-in is accessible from the internet
  • No proper access control measures are in place

โฑ Urgency: High urgency due to active exploitation in the wild.

๐Ÿ’ก Context: The access control mechanisms in the server or plug-in are improperly configured, allowing unauthorized users to bypass security checks.


CISA Adds One Known Exploited Vulnerability to Catalog

CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2026-60004

โ“ Why Should I Care?
Yes, if you run Gitea versions 1.15.0 - 1.15.5, 1.16.0 - 1.16.2: code injection vulnerability, actively exploited in the wild. Patch now.

๐ŸŽฏ Affected versions: Gitea 1.15.0 - 1.15.5, 1.16.0 - 1.16.2
Not affected: Gitea 1.17.0 and later

๐ŸŽญ In plain English:
An attacker can inject malicious code into your Gitea server, allowing them to execute arbitrary commands on your system. For example, they could upload a backdoor, steal your source code, or take control of your server without you knowing.

๐Ÿ”ง Prerequisites:

  • Gitea server is running an affected version
  • Attacker has access to the Gitea web interface

โฑ Urgency: High urgency due to active exploitation in the wild.

๐Ÿ’ก Context: The vulnerability allows attackers to inject malicious code through a specific input field, which is then executed by the server.

โœ… Fixed in: 1.17.0, 1.16.3, 1.15.6


CISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA Advisories [CISA KEV] | CVSS N/A | CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, CVE-2026-8452

โ“ Why Should I Care?
Yes, if you run any of the affected versions of Red Hat, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, or Citrix NetScaler: these vulnerabilities are actively exploited and pose significant risks.

๐ŸŽฏ Affected versions: Red Hat Libuser, Red Hat Automatic Bug Reporting Tool, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, Citrix NetScaler ADC and NetScaler Gateway

๐ŸŽญ In plain English:
These vulnerabilities allow attackers to take control of your systems, escalate privileges, or execute arbitrary code. For example, an attacker could exploit a flaw in Microsoft SQL Server to run any command on your server, potentially stealing data or installing malware.

๐Ÿ”ง Prerequisites:

  • Running an affected version of the software
  • No specific prerequisites mentioned

โฑ Urgency: High urgency due to active exploitation in the wild.


All-Line Equipment Company Fuel-Boss

CISA Advisories [CISA KEV] | CVSS 8.7 | CVE-2018-19518, CVE-2019-11043

โ“ Why Should I Care?
Yes, if you run All-Line Equipment Company Fuel-Boss V1 Standard, Portal, Master/Slave, or Backflush Systems with PHP_7.1.5: unauthenticated RCE, potentially exploited. Patch now.

๐ŸŽฏ Affected versions: Fuel-Boss V1 Standard: >=|<=PHP_7.1.5_7.1.5, Fuel-Boss V1 Portal: >=|<=PHP_7.1.5_7.1.5, Fuel-Boss V1 Master/Slave: >=|<=PHP_7.1.5_7.1.5, Fuel-Boss V1 Backflush Systems: >=|<=PHP_7.1.5_7.1.5

๐ŸŽญ In plain English:
Your Fuel-Boss system can be remotely controlled by attackers who can inject commands or overflow buffers, allowing them to execute arbitrary code. This means an attacker could take over your system, change settings, or even steal data without you knowing.

๐Ÿ”ง Prerequisites:

  • Unpatched PHP_7.1.5 version
  • Access to the system via IMAP or FPM

โฑ Urgency: High urgency due to the potential for remote code execution and the lack of patches for some versions.

๐Ÿ’ก Context: The system fails to properly sanitize input for IMAP commands and buffer sizes, allowing attackers to inject commands or overflow buffers to execute arbitrary code.

โœ… Fixed in: Not specified for all versions


CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Advisories [CISA KEV] | CVE-2023-49105, CVE-2026-53362, CVE-2026-66384

โ“ Why Should I Care?
Yes, if you run any of the affected versions of ownCloud, Linux Kernel, or JFrog Artifactory: these vulnerabilities are actively exploited and pose significant risks.

๐ŸŽฏ Affected versions: ownCloud 2.0.x - 2.0.18, Linux Kernel 5.10.x - 5.19.x, JFrog Artifactory 7.20.x - 7.20.12
Not affected: ownCloud 2.1.x and above, Linux Kernel 6.0.x and above, JFrog Artifactory 7.21.x and above

๐ŸŽญ In plain English:
An attacker can exploit these vulnerabilities to gain unauthorized access to your systems, potentially taking full control. For example, if you use ownCloud, an attacker could log in without credentials and access all your files. If you use Linux Kernel, they could execute arbitrary code on your system. If you use JFrog Artifactory, they could access sensitive files and directories.

๐Ÿ”ง Prerequisites:

  • Running affected versions of ownCloud
  • Running affected versions of Linux Kernel
  • Running affected versions of JFrog Artifactory

โฑ Urgency: High urgency due to active exploitation in the wild.

๐Ÿ’ก Context: The vulnerabilities include improper authentication, unspecified kernel issues, and improper directory restrictions, allowing attackers to bypass security measures and gain unauthorized access.

โœ… Fixed in: ownCloud 2.1.0, Linux Kernel 6.0.0, JFrog Artifactory 7.21.0


FURUNO FA-50 Class B AIS Transponder

CISA Advisories | CVSS 9.1 | CVE-2026-59769

โ“ Why Should I Care?
Yes, if you run any version of FURUNO FA-50 Class B AIS Transponder: hard-coded credentials and missing authentication allow attackers to alter device settings. Patch now if possible.

๐ŸŽฏ Affected versions: FURUNO FA-50 Class B AIS Transponder: vers:all/*

๐ŸŽญ In plain English:
Your AIS transponder has a secret password that anyone can use to change its settings. An attacker who gains access to your ship's network can alter these settings, potentially disabling safety features or misreporting your ship's position.

๐Ÿ”ง Prerequisites:

  • Knowledge of hard-coded credentials
  • Access to the in-vessel network

โฑ Urgency: High urgency due to the critical nature of the device and the potential for unauthorized changes to safety-critical settings.

๐Ÿ’ก Context: The device uses hard-coded credentials and lacks proper authentication mechanisms for critical functions, allowing unauthorized users to alter settings.


Ebyte NE2-D11

CISA Advisories | CVSS 9.8 | CVE-2026-73125, CVE-2026-73809, CVE-2026-73839

โ“ Why Should I Care?
Yes, if you run Ebyte NE2-D11 Firmware FW-9167-0-11: critical vulnerabilities allow unauthorized access, sensitive data disclosure, and device disruption. Patch urgently.

๐ŸŽฏ Affected versions: Ebyte NE2-D11 Firmware FW-9167-0-11

๐ŸŽญ In plain English:
Your device's web management interface is wide open. An attacker can log in without a password, steal sensitive data, change settings, and even crash the device. Imagine someone remotely changing your firewall rules or stealing your login credentials just by sniffing network traffic.

๐Ÿ”ง Prerequisites:

  • Device running Ebyte NE2-D11 Firmware FW-9167-0-11
  • Network access to the device

โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and the potential for unauthorized access and disruption.

๐Ÿ’ก Context: The device lacks proper authentication mechanisms and encrypts sensitive data improperly, allowing attackers to exploit these flaws easily.


Applied Systems Engineering ASE2000 V2 Communications Test Set

CISA Advisories | CVSS 9.8 | CVE-2018-1285, CVE-2026-18717

โ“ Why Should I Care?
Yes, if you run Applied Systems Engineering ASE2000 V2 versions 2.25-2.37: critical vulnerabilities allow arbitrary file access, network requests, and TLS interception. Patch now.

๐ŸŽฏ Affected versions: ASE2000 V2 versions 2.25-2.37
Not affected: 2.38 and later

๐ŸŽญ In plain English:
An attacker can read or write any file on your device, make it send network requests, or intercept secure communications. For example, an attacker could steal sensitive files, send fake commands to your network, or eavesdrop on your secure communications without you knowing.

๐Ÿ”ง Prerequisites:

  • Access to the device's file system or network communication
  • The device is running an affected version

โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and potential for active exploitation.

๐Ÿ’ก Context: The device improperly handles XML external entity references and fails to validate TLS certificates correctly, allowing for unauthorized access and interception.

โœ… Fixed in: 2.38


Ebyte NA111-M

CISA Advisories | CVSS 9.8 | CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977

โ“ Why Should I Care?
Yes, if you run Ebyte NA111-M Firmware 9013-2-17: multiple critical vulnerabilities allow unauthenticated access and full device compromise. Patch urgently.

๐ŸŽฏ Affected versions: NA111-M Firmware 9013-2-17

๐ŸŽญ In plain English:
Your device's web management interface lacks proper authentication, allowing anyone to access sensitive configuration information, modify settings, or disrupt the device. An attacker could impersonate an admin, change settings, and take full control of your device without any trace.

๐Ÿ”ง Prerequisites:

  • Device running Firmware 9013-2-17
  • No patch applied

โฑ Urgency: High urgency due to multiple critical vulnerabilities that allow full device compromise.

๐Ÿ’ก Context: The web management interface does not consistently enforce authentication before granting access to administrative functionality, and authentication tokens are insufficiently protected.


Xiiaozet LK100W

CISA Advisories | CVSS 9.8 | CVE-2026-78037, CVE-2026-78239, CVE-2026-76943

โ“ Why Should I Care?
Yes, if you run Xiiaozet LK100W <2.1.240: unauthenticated RCE, OS command injection, and authentication bypass. Actively exploitable.

๐ŸŽฏ Affected versions: Xiiaozet LK100W <2.1.240

๐ŸŽญ In plain English:
Your device's web interface allows attackers to run any command on the device, bypass authentication, and take full control. An attacker could steal sensitive data, alter device settings, or use the device for malicious activities without your knowledge.

๐Ÿ”ง Prerequisites:

  • Device version <2.1.240

โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and potential for active exploitation.

๐Ÿ’ก Context: The device's web interface fails to properly sanitize input, allowing for OS command injection, and has critical functions that do not require authentication.

โœ… Fixed in: 2.1.240


Why Should I Care? ๐ŸŸก MEDIUM (8)


Zoneminder

CISA Advisories | CVSS 8.8 | CVE-2026-76060

โ“ Why Should I Care?
Yes, if you run Zoneminder 1.37.48 or 1.38.3: authenticated users can execute arbitrary commands on your server, leading to full Remote Code Execution (RCE). Patch now.

๐ŸŽฏ Affected versions: Zoneminder 1.37.48, 1.38.3

๐ŸŽญ In plain English:
An authenticated user can inject malicious commands into the server through the event export feature, allowing them to take full control of your server. For example, an attacker could log in with a valid account and execute commands to steal data, install malware, or shut down services.

๐Ÿ”ง Prerequisites:

  • Authenticated user with View Events permission

โฑ Urgency: High urgency due to the potential for full server control and active exploitation.

๐Ÿ’ก Context: The exportFile HTTP request parameter is passed unsanitized into a shell command via PHP's exec(), allowing command injection.

โœ… Fixed in: 1.38.3


Rently Smart Home

CISA Advisories | CVSS 8.1 | CVE-2026-75960

โ“ Why Should I Care?
Yes, if you run Rently Smart Home <=20.1.0: attackers can access sensitive information and override user permissions, including the Master Pin.

๐ŸŽฏ Affected versions: Rently Smart Home <=20.1.0

๐ŸŽญ In plain English:
Your smart home system has a weak password protection issue. An attacker could steal your Master Pin and take full control of your smart home devices, changing settings and permissions without your knowledge.

๐Ÿ”ง Prerequisites:

  • Smart Home version <=20.1.0

โฑ Urgency: High urgency due to the potential for unauthorized access and control over smart home devices.

๐Ÿ’ก Context: The system stores credentials in an insecure manner, allowing unauthorized access to sensitive information.

โœ… Fixed in: 20.1.1


Bendix EC80 Brake ECU

CISA Advisories | CVSS 7.5 | CVE-2026-67560, CVE-2026-68967

โ“ Why Should I Care?
Yes, if you run any of the affected Bendix EC80 Brake ECU versions: an attacker can disable critical vehicle functions like ABS and steering assist, potentially causing a crash.

๐ŸŽฏ Affected versions: EC80ESP+ J1708 Z228999, EC80ESP+ 6S/6M Z228999, EC80ESP+ PLC Z228999, EC80ESP+ 2nd CAN Z228999, EC80ESP+ Integrated TPMS Z228999, EC80ESP 6S/6M Z266494, EC80ESP PLC Z266494, EC80ESP 2nd CAN Z266494, EC80ESP CAN Gateway Z266494, EC80ESP 4S/4M Z286098, EC80ESP PLC Z286098

๐ŸŽญ In plain English:
Your vehicle's brake control unit has a flaw that allows an attacker to send malicious data over the CAN bus, potentially disabling critical safety features like ABS and steering assist. This could lead to a loss of vehicle control and a crash.

๐Ÿ”ง Prerequisites:

  • Access to the CAN bus

โฑ Urgency: High urgency due to the potential for loss of vehicle control and safety features.

๐Ÿ’ก Context: The firmware contains a stack-based buffer overflow and out-of-bounds write vulnerabilities, allowing an attacker to inject arbitrary CAN bus traffic and execute arbitrary code.

โœ… Fixed in: Z300822, Z302578, Z302579


PayRange API

CISA Advisories | CVSS 8.8 | CVE-2026-18965

โ“ Why Should I Care?
Yes, if you run any version of PayRange API: unauthenticated access to sensitive information and potential device modification, actively exploitable.

๐ŸŽฏ Affected versions: PayRange API vers:all/*

๐ŸŽญ In plain English:
Your PayRange API is missing proper security checks, allowing anyone to access sensitive information and potentially alter device settings, leading to a denial of service or image tampering. An attacker could view your financial data or change device configurations without your knowledge.

๐Ÿ”ง Prerequisites:

  • No authentication required

โฑ Urgency: High urgency due to the potential for unauthenticated access and active exploitation.

๐Ÿ’ก Context: The management endpoints lack proper authorization checks, allowing unauthorized access to sensitive information and device control.


Siemens SIMATIC IoT2050 Advanced

CISA Advisories | CVSS 10 | CVE-2026-58115

โ“ Why Should I Care?
Yes, if you run SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) versions < 4.3.4.1: unauthenticated attackers can execute arbitrary code with maximum privileges. Patch now.

๐ŸŽฏ Affected versions: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < 4.3.4.1

๐ŸŽญ In plain English:
Your IoT2050 device has a backdoor that lets anyone on the internet log in and run any command they want on your device. An attacker could use this to take full control of your device, steal data, or even brick it.

๐Ÿ”ง Prerequisites:

  • Node-RED must be installed
  • Device must be accessible from the internet

โฑ Urgency: High urgency due to the critical nature of the vulnerability and the potential for unauthenticated remote code execution.

๐Ÿ’ก Context: The Node-RED HTTP interface does not enforce authentication, allowing unauthenticated access to programming nodes that can execute system commands.

โœ… Fixed in: 4.3.4.1


Mitsubishi Electric Multiple FA Products (Update D)

CISA Advisories | CVE-2025-3511

โ“ Why Should I Care?
Yes, if you run any of the affected Mitsubishi Electric CC-Link IE TSN modules <=09: remote attackers can cause a DoS, timeout, or communication delay. Patch now.

๐ŸŽฏ Affected versions: Mitsubishi Electric CC-Link IE TSN modules <=09 (specific models listed in advisory)

๐ŸŽญ In plain English:
An attacker can send a specially crafted packet to your Mitsubishi Electric CC-Link IE TSN modules, causing them to stop working, time out, or delay communication. This means your industrial control systems could freeze or become unresponsive, potentially disrupting your operations.

๐Ÿ”ง Prerequisites:

  • The attacker must be able to send UDP packets to the affected module.

โฑ Urgency: Moderately urgent due to the potential for operational disruption caused by DoS conditions.


Mitsubishi Electric CNC Series (Update A)

CISA Advisories | CVSS 5.9 | CVE-2025-2399

โ“ Why Should I Care?
Yes, if you run any affected version of Mitsubishi Electric CNC Series (Update A): unpatched systems can be remotely crashed, causing a denial-of-service. Apply the fix now.

๐ŸŽฏ Affected versions: Mitsubishi Electric M800VW (BND-2051W000) <=BB, M800VS (BND-2052W000) <=BB, M80V (BND-2053W000) <=BB, M80VW (BND-2054W000) <=BB, M800W (BND-2005W000) <=FM, M800S (BND-2006W000) <=FM, M80 (BND-2007W000) <=FM, M80W (BND-2008W000) <=FM, E80 (BND-2009W000) <=FM, C80 (BND-2036W000) vers:all/*, M750VW (BND-1015W002) <=LJ, M730VW (BND-1015W000) <=LJ, M720VW (BND-1015W000) <=LJ, M750VS (BND-1012W002) <=LJ, M730VS (BND-1012W000) <=LJ, M720VS (BND-1012W000) <=LJ, M70V (BND-1018W000) <=LJ, E70 (BND-1022W000) <=LJ

๐ŸŽญ In plain English:
Your CNC machine can be made to crash remotely, causing it to stop working. An attacker could send a bad command that makes the machine freeze, stopping production until it's fixed.

๐Ÿ”ง Prerequisites:

  • TCP port 683 must be accessible from the attacker's location

โฑ Urgency: Medium urgency: this vulnerability can cause a denial-of-service, but does not allow for data theft or remote code execution.

๐Ÿ’ก Context: The software fails to properly validate input, allowing an attacker to send a specially crafted packet that triggers an out-of-bounds read.

โœ… Fixed in: BC or later for M800VW, M800VS, M80V, M80VW, FN or later for M800W, M800S, M80, M80W, E80


Vulnerability in OpenSSL library

Fortinet PSIRT | CVSS 7.5 | CVE-2022-0778

โ“ Why Should I Care?
Yes, if you run Fortinet products using affected OpenSSL versions: unpatched systems can be made unresponsive via crafted certificates, leading to a denial of service.

๐ŸŽฏ Affected versions: FortiOS 7.0.x - 7.2.13, 7.4.0 - 7.4.2

๐ŸŽญ In plain English:
An attacker can send your Fortinet device a specially crafted certificate that makes it freeze and stop working. This means your security device could become unresponsive, leaving your network vulnerable until it's fixed.

๐Ÿ”ง Prerequisites:

  • The device must be configured to parse externally supplied certificates

โฑ Urgency: Moderately urgent due to the potential for denial of service attacks, though no active exploitation has been reported.

๐Ÿ’ก Context: The BN_mod_sqrt() function in OpenSSL has a bug that causes it to loop indefinitely when processing certain invalid certificates, leading to a denial of service.

โœ… Fixed in: 7.0.14, 7.2.14, 7.4.3


Why Should I Care? ๐Ÿ”ต On the Radar (73)


โšช 54 low-priority items filtered.


๐Ÿฆ… Aggregated and triaged by Donna AI  |  Sources: 9 vendor feeds  |  CISA KEV

Read more

Why Should I Care? โ€” 2026-09-24 | ๐Ÿ”ด 0 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-24 27 vendor intel items scanned ย |ย  ๐Ÿ”ด 0 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED โœ… No critical items today. Everything else can wait. ๐Ÿ”ต 15 items on the radar โ€” see below โ†“ Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? ๐ŸŸก MEDIUM

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-23 | ๐Ÿ”ด 5 HIGH ยท ๐ŸŸก 3 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-23 35 vendor intel items scanned ย |ย  ๐Ÿ”ด 5 HIGH ย |ย  ๐ŸŸก 3 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) โ€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-22 | ๐Ÿ”ด 1 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 17 RADAR ยท โšช 66 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-22 18 vendor intel items scanned ย |ย  ๐Ÿ”ด 1 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 17 RADAR ย |ย  โšช 66 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) โ€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-21 | ๐Ÿ”ด 23 HIGH ยท ๐ŸŸก 32 MEDIUM ยท ๐Ÿ”ต 209 RADAR ยท โšช 73 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-21 264 vendor intel items scanned ย |ย  ๐Ÿ”ด 23 HIGH ย |ย  ๐ŸŸก 32 MEDIUM ย |ย  ๐Ÿ”ต 209 RADAR ย |ย  โšช 73 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) โ€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic